Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1134.002 Create Process with Token |
MalwareAria-body | Aria-body has the ability to execute a process using |
| T1134.002 Create Process with Token |
MalwareWhisperGate | The WhisperGate third stage can use the AdvancedRun.exe tool to execute commands in the context of the Windows TrustedInstaller group via `%TEMP%\AdvancedRun.exe" /EXEFilename "C:\Windows\System32\sc.exe" /WindowState 0 /CommandLine "stop WinDefend" /StartDirectory "" /RunAs 8 /Run`. |
| T1134.002 Create Process with Token |
MalwarePipeMon | PipeMon can attempt to gain administrative privileges using token impersonation. |
| T1134.002 Create Process with Token |
MalwareKONNI | KONNI has duplicated the token of a high integrity process to spawn an instance of cmd.exe under an impersonated user. |
| T1134.002 Create Process with Token |
MalwareREvil | REvil can launch an instance of itself with administrative rights using runas. |
| T1134.002 Create Process with Token |
MalwareZxShell | ZxShell has a command called RunAs, which creates a new process as another user or process context. |
| T1134.002 Create Process with Token |
MalwareAzorult | Azorult can call WTSQueryUserToken and CreateProcessAsUser to start a new process with local system privileges. |
| T1134.002 Create Process with Token |
ToolEmpire | Empire can use |
| T1134.002 Create Process with Token |
ToolPoshC2 | PoshC2 can use Invoke-RunAs to make tokens. |
| T1134.003 Make and Impersonate Token |
MalwareMafalda | Mafalda can create a token for a different user. |
| T1134.003 Make and Impersonate Token |
MalwareCobalt Strike | Cobalt Strike can make tokens from known credentials. |
| T1134.003 Make and Impersonate Token |
ToolSILENTTRINITY | SILENTTRINITY can make tokens from known credentials. |
| T1134.004 Parent PID Spoofing |
MalwareDarkGate | DarkGate relies on parent PID spoofing as part of its "rootkit-like" functionality to evade detection via Task Manager or Process Explorer. |
| T1134.004 Parent PID Spoofing |
MalwarePipeMon | PipeMon can use parent PID spoofing to elevate privileges. |
| T1134.004 Parent PID Spoofing |
MalwareKONNI | KONNI has used parent PID spoofing to spawn a new `cmd` process using `CreateProcessW` and a handle to `Taskmgr.exe`. |
| T1134.004 Parent PID Spoofing |
MalwareCobalt Strike | Cobalt Strike can spawn processes with alternate PPIDs. |
| T1134.005 SID-History Injection |
ToolEmpire | Empire can add a SID-History to a user if on a domain controller. |
| T1134.005 SID-History Injection |
ToolMimikatz | Mimikatz's |
| T1135 Network Share Discovery |
MalwareTrickBot | TrickBot module shareDll/mshareDll discovers network shares via the WNetOpenEnumA API. |
| T1135 Network Share Discovery |
MalwareQuietSieve | QuietSieve can identify and search networked drives for specific file name extensions. |
| T1135 Network Share Discovery |
MalwareMURKYTOP | MURKYTOP has the capability to retrieve information about shares on remote hosts. |
| T1135 Network Share Discovery |
MalwareStuxnet | Stuxnet enumerates the directories of a network resource. |
| T1135 Network Share Discovery |
MalwareAvosLocker | AvosLocker has enumerated shared drives on a compromised network. |
| T1135 Network Share Discovery |
MalwareKOPILUWAK | KOPILUWAK can use netstat and Net to discover network shares. |
| T1135 Network Share Discovery |
MalwareSardonic | Sardonic has the ability to execute the `net view` command. |
| T1135 Network Share Discovery |
MalwareRansomHub | RansomHub has the ability to target specific network shares for encryption. |
| T1135 Network Share Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has identified networked drives. |
| T1135 Network Share Discovery |
MalwareBad Rabbit | Bad Rabbit enumerates open SMB shares on internal victim networks. |
| T1135 Network Share Discovery |
MalwareEmotet | Emotet has enumerated non-hidden network shares using `WNetEnumResourceW`. |
| T1135 Network Share Discovery |
MalwareOlympic Destroyer | Olympic Destroyer will attempt to enumerate mapped network shares to later attempt to wipe all files on those shares. |
| T1135 Network Share Discovery |
MalwareDUSTTRAP | DUSTTRAP can identify and enumerate victim system network shares. |
| T1135 Network Share Discovery |
MalwareBADHATCH | BADHATCH can check a user's access to the C$ share on a compromised machine. |
| T1135 Network Share Discovery |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware can identify network shares connected to the victim machine. |
| T1135 Network Share Discovery |
MalwareWastedLocker | WastedLocker can identify network adjacent and accessible drives. |
| T1135 Network Share Discovery |
MalwareInvisiMole | InvisiMole can gather network share information. |
| T1135 Network Share Discovery |
MalwareWhisperGate | WhisperGate can enumerate connected remote logical drives. |
| T1135 Network Share Discovery |
MalwareConti | Conti can enumerate remote open SMB network shares using |
| T1135 Network Share Discovery |
MalwareDiavol | Diavol has a `ENMDSKS` command to enumerates available network shares. |
| T1135 Network Share Discovery |
MalwareBlackCat | BlackCat has the ability to discover network shares on compromised networks. |
| T1135 Network Share Discovery |
MalwareIcedID | IcedID has used the `net view /all` command to show available shares. |
| T1135 Network Share Discovery |
MalwareShimRat | ShimRat can enumerate connected drives for infected host machines. |
| T1135 Network Share Discovery |
MalwareAvaddon | Avaddon has enumerated shared folders and mapped volumes. |
| T1135 Network Share Discovery |
MalwareFlagpro | Flagpro has been used to execute `net view` to discover mapped network shares. |
| T1135 Network Share Discovery |
MalwareHELLOKITTY | HELLOKITTY has the ability to enumerate network resources. |
| T1135 Network Share Discovery |
MalwareBabuk | Babuk has the ability to enumerate network shares. |
| T1135 Network Share Discovery |
MalwarePlugX | PlugX has a module to enumerate network shares. |
| T1135 Network Share Discovery |
MalwareCuba | Cuba can discover shared resources using the |
| T1135 Network Share Discovery |
MalwareDEATHRANSOM | DEATHRANSOM has the ability to use loop operations to enumerate network resources. |
| T1135 Network Share Discovery |
MalwareClambling | Clambling has the ability to enumerate network shares. |
| T1135 Network Share Discovery |
MalwareAkira | Akira can identify remote file shares for encryption. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.